Overview
Skills
Job Details
Role Summary
The ServiceNow Vulnerability Response Lead will be responsible for designing, implementing, and managing the organization s vulnerability response processes within ServiceNow. This role will drive automation, process optimization, and reporting to strengthen the enterprise vulnerability management program. The ideal candidate will partner with Security, IT Operations, and Business stakeholders to enhance vulnerability lifecycle management and ensure timely remediation.
Key Responsibilities
Design, implement, and manage ServiceNow Vulnerability Response workflows, SLAs, and escalation paths.
Integrate ServiceNow with vulnerability scanning tools such as Tenable, Qualys, and others.
Collaborate with Security, IT Operations, and Business Units to prioritize and remediate vulnerabilities effectively.
Identify and implement automation opportunities, including enrichment, auto-assignment, and closure validation.
Define and maintain process controls to ensure accuracy and data integrity across all vulnerability response activities.
Build and maintain dashboards and reports for leadership, measuring metrics such as time to remediate, SLA compliance, and vulnerability aging.
Develop training materials and lead enablement sessions to ensure user adoption.
Manage communication and change management efforts to drive process adoption and continuous improvement.
Required Experience & Skills
Proven experience in Vulnerability Management, Security Operations (SecOps), or Governance, Risk & Compliance (GRC).
Strong knowledge of ServiceNow Vulnerability Response module and related integrations (e.g., Tenable, Qualys).
Experience designing workflows, automations, and dashboards in ServiceNow.
Solid understanding of vulnerability remediation processes and supporting technologies.
Excellent communication, documentation, and stakeholder management skills.
Strong analytical and problem-solving capabilities with attention to detail.
Preferred Qualifications
ServiceNow Certified Implementation Specialist Vulnerability Response (CISVR) or related certification.
Experience with scripting (e.g., JavaScript, PowerShell, Python) for automation.
Knowledge of IT Service Management (ITSM) and CMDB data models.